Splunk ITSI

IT Essential Work - Failed to retrieve entity status breakdown. Error: insufficient permission to access this resource

corti77
Communicator

In the way to test ITSI, I first installed IT Essentials Work on my single standalone splunk server

following the instruction from the link 
https://docs.splunk.com/Documentation/ITEWork/4.9.2/Install/Install#Install_IT_Essentials_Work_on_a_...

I simply stop the service, unzip the tgz and start splunk.

once done, I go to the essential work app and I get the following error on the infrastructure overview

corti77_1-1627990033567.png

any idea of what could be happening? I could not find anything in the logs so far.

thanks

 

0 Karma
1 Solution

corti77
Communicator

I finally solved the permissions issue. Thanks a lot for the hint.

I just added the itoa roles in the inherence of the role admin. My user belonged to the admin role, so after I logged out and in, the error in the itsi dashboard disappeared.

 

https://community.splunk.com/t5/Splunk-IT-Service-Intelligence/Why-is-the-fresh-install-of-ITSI-3-1-...

 

View solution in original post

sweetie
Explorer

Hi @corti77 , Where exactly do we need to add the itoa_role in Splunk to solve this issue? Thanks

0 Karma

yannK
Splunk Employee
Splunk Employee

Look in the ITSI default authorize.conf, you will see what is expected.

( file in $SPLUNK_HOME/etc/apps/itsi/default/authorize.conf)

[role_admin]
importRoles = itoa_admin;itoa_analyst;itoa_user;power;user

 

if you have a customized role, (usually in $SPLUNK_HOME/etc/system/local/authorize.conf), this one has precedence, and you may be missing the itoa rolse in inheritance of your admin role.

You can simply edit your "admin" role from the UI > setting > roles, and add the missing inheritances. (and keep any extra ou may have added)

 

0 Karma

sweetie
Explorer

Thank you, it helped. 

0 Karma

yannK
Splunk Employee
Splunk Employee

Could it be a role issue, 
check if your user is member or inherit from the role itoa_user (or itoa_analyst, or itoa_admin) ?

corti77
Communicator

I just double checked it and indeed I am using an admin user that does not have those role assigned. The weird thing is that I tried to add the roles to my user and they dont stick on the user. I add roles, click on Save button and nothing seems to happen.

Any idea about what would be happening?

0 Karma

corti77
Communicator

I finally solved the permissions issue. Thanks a lot for the hint.

I just added the itoa roles in the inherence of the role admin. My user belonged to the admin role, so after I logged out and in, the error in the itsi dashboard disappeared.

 

https://community.splunk.com/t5/Splunk-IT-Service-Intelligence/Why-is-the-fresh-install-of-ITSI-3-1-...

 

rassul_kv
Engager

I have the same problem

0 Karma
Get Updates on the Splunk Community!

Alerting Best Practices: How to Create Good Detectors

At their best, detectors and the alerts they trigger notify teams when applications aren’t performing as ...

Discover Powerful New Features in Splunk Cloud Platform: Enhanced Analytics, ...

Hey Splunky people! We are excited to share the latest updates in Splunk Cloud Platform 9.3.2408. In this ...

Splunk Classroom Chronicles: Training Tales and Testimonials

Welcome to the "Splunk Classroom Chronicles" series, created to help curious, career-minded learners get ...